> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sapt.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create OAuth client

> Register a developer OAuth client owned by the caller. The token issued after consent carries `account:full` and acts on behalf of every consenting user across all of their Sapt projects. The plaintext `clientSecret` is returned only at create time — capture it immediately. Public PKCE clients receive `clientSecret: null`.



## OpenAPI

````yaml https://api.sapt.ai/openapi.json post /oauth-clients
openapi: 3.1.0
info:
  title: Sapt Platform API
  version: 1.0.0
  description: >-
    API for Sapt platform - project management, authentication, and email
    services
servers:
  - url: https://api.sapt.ai
    description: Production
  - url: http://localhost:8787
    description: Local development
security: []
tags:
  - name: Accounts
    description: >-
      The social accounts connected to a project. Start here — the `id` of an
      account is the `socialAccountId` that every posting, scheduling and
      analytics call takes.
  - name: Actions
  - name: Ads
  - name: Agents
  - name: Analytics
    description: >-
      Account- and post-level organic performance for connected Instagram and
      Facebook accounts.
  - name: Assets
  - name: Auth
  - name: CMS
  - name: CRM
  - name: Calendar
  - name: Comments
    description: >-
      Read, reply to, hide and delete comments on published Instagram and
      Facebook posts.
  - name: Content Calendar
    description: >-
      Create, schedule, update and publish organic posts, and stage the media
      they carry. Publishing a post whose status is `failed` retries it.
  - name: Contracts
  - name: Conversions
    description: >-
      Meta server-side Conversions API (CAPI): discover pixels, connect a pixel
      + CAPI token, and send deduped server-side conversions.
  - name: Dashboard Sidebar
  - name: Emails
  - name: Engagement
    description: >-
      Act as the Page or account on published posts: comment, like, unlike, and
      delete a published post.
  - name: Geo
  - name: Google Ads
  - name: Google Analytics
  - name: Google Business
  - name: Integrations
    description: >-
      Connect third-party providers (Meta, Gmail, Google Business Profile, …).
      List providers, mint OAuth connect links, and poll connection status.
  - name: Invitations
  - name: Memory
  - name: OAuth Clients
  - name: Project Roles
  - name: Project Templates
  - name: Projects
  - name: Schedules
  - name: Service Accounts
  - name: Socials
    description: >-
      Organic social: the connected accounts, the content calendar, media
      staging, publishing, comments and engagement across Instagram, Facebook,
      TikTok, YouTube and Google Business Profile.
  - name: Team
  - name: Users
  - name: Web Analytics
  - name: Workflows
paths:
  /oauth-clients:
    post:
      tags:
        - OAuth Clients
      summary: Create OAuth client
      description: >-
        Register a developer OAuth client owned by the caller. The token issued
        after consent carries `account:full` and acts on behalf of every
        consenting user across all of their Sapt projects. The plaintext
        `clientSecret` is returned only at create time — capture it immediately.
        Public PKCE clients receive `clientSecret: null`.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 200
                redirectURLs:
                  type: array
                  items:
                    type: string
                    format: uri
                  minItems: 1
                clientType:
                  type: string
                  enum:
                    - web
                    - public
                description:
                  type: string
                  maxLength: 1000
                homepageUrl:
                  type: string
                  format: uri
                icon:
                  type: string
                  format: uri
              required:
                - name
                - redirectURLs
      responses:
        '201':
          description: OAuth client created
          content:
            application/json:
              schema:
                type: object
                properties:
                  clientId:
                    type: string
                  clientSecret:
                    type:
                      - string
                      - 'null'
                  client:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      clientId:
                        type: string
                      name:
                        type: string
                      type:
                        type: string
                      redirectURLs:
                        type: array
                        items:
                          type: string
                      disabled:
                        type: boolean
                      projectId:
                        type:
                          - string
                          - 'null'
                        format: uuid
                      userId:
                        type:
                          - string
                          - 'null'
                      kind:
                        type:
                          - string
                          - 'null'
                      icon:
                        type:
                          - string
                          - 'null'
                      description:
                        type:
                          - string
                          - 'null'
                      homepageUrl:
                        type:
                          - string
                          - 'null'
                      metadata:
                        type:
                          - string
                          - 'null'
                      defaultMemberRoleIds:
                        type: array
                        items:
                          type: string
                      allowedScopes:
                        type: array
                        items:
                          type: string
                      authenticationScheme:
                        type:
                          - string
                          - 'null'
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                    required:
                      - id
                      - clientId
                      - name
                      - type
                      - redirectURLs
                      - disabled
                      - projectId
                      - userId
                      - kind
                      - icon
                      - description
                      - homepageUrl
                      - metadata
                      - defaultMemberRoleIds
                      - allowedScopes
                      - authenticationScheme
                      - createdAt
                      - updatedAt
                required:
                  - clientId
                  - clientSecret
                  - client
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    description: Error message
                  code:
                    type: string
                    description: Error code for programmatic handling
                required:
                  - message
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    description: Error message
                  code:
                    type: string
                    description: Error code for programmatic handling
                required:
                  - message
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        JWT token obtained from /api/auth/token endpoint. Token is verified
        using JWKS and must include a valid user identifier.

````